mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-03 16:05:24 -04:00
Every request through index.php starts a session and always dirties it: zm_session_set_remote_addr() writes remoteAddr, and index.php stores skin, css and navbar_type. ZMSessionHandler::write() then persisted that session unconditionally, so any request arriving without a ZMSESSID cookie left a Sessions row behind that nothing would ever load again. Viewing an event polls the event's server every ZM_WEB_REFRESH_STATUS seconds via monitorUrl, which is absolute when the monitor has a Server row. Those cross-origin ajax polls carry auth in the URL and no cookie, so each one added a Sessions row every few seconds. Bot scans of the login page did the same. Persist a session only when the client presented our cookie, or when zm_session_persist() marks it as one we are issuing: login, and the postLoginQuery stashed before redirecting to the login page. Verified on a live install by logging row counts from the save handler: three cookieless requests skipped the write and left the count unchanged, while a cookie-jar run wrote on the request that returned the cookie. php -l clean on both files. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GAFKf86P78WqniPEP2b45J